
Can AI copy a person's voice?
Key Facts
- AI voice cloning replicates a person's voice with startling accuracy using just a few minutes of recorded audio according to university security research
- The United States reported $10 billion in losses in 2024 from Southeast Asian scam operations weaponizing AI voice cloning per United Nations reporting
- The FCC unanimously ruled in February 2024 that AI-generated voices count as artificial under the TCPA, requiring prior express consent per the FCC Declaratory Ruling
- A proposed $2 million forfeiture was issued against Lingo Telecom for 3,978 spoofed robocalls using a deepfake of President Biden's voice per FCC enforcement action
- Copyright does not protect AI voice files — the U.S. Copyright Office requires a human author, leaving raw AI audio in the public domain per voice industry analysis
- The Right of Publicity — established in Bette Midler v. Ford and Tom Waits v. Frito-Lay — is the real legal shield requiring consent for commercial voice use per legal precedent
- An Australian couple with master's degrees lost over $2.5 million to an extraordinarily believable AI voice scammer using a British accent per UN crime reporting
Yes, AI Can Copy a Voice — and It Only Takes Minutes of Audio
Imagine hearing your own voice on the phone — saying words you never spoke. That scenario is no longer science fiction; it is a technical reality that takes just a few minutes of audio to create.
Modern text-to-speech AI can replicate a person's voice with startling accuracy from just a few minutes of recorded audio, capturing tone, cadence, and inflection, according to university security research. The U.S. Federal Trade Commission confirms the same, noting that voice cloning "is becoming increasingly sophisticated due to improving text-to-speech AI" as part of its Voice Cloning Challenge.
This is not a fringe capability. Commercial voice recreation has been used in mainstream productions like The Mandalorian, where archival recordings were combined with speech-to-speech technology — with full legal clearance, as voice technology firms document. The same underlying technology, pointed at a stranger's podcast or voicemail, produces a convincing copy of anyone.
The scale of abuse is already enormous. Criminal networks in Southeast Asia explicitly weaponize AI for deepfakes and voice cloning, and the United States alone reported $10 billion in losses in 2024 from these scam operations, according to United Nations reporting. Common attack patterns include:
- Emergency family scams that clone a relative's voice to demand money fast
- Executive impersonation, or "vishing," that mimics a boss or colleague to trigger wire transfers
- Political manipulation, including 3,978 spoofed robocalls using an AI-cloned presidential voice before the New Hampshire primary, which drew a proposed $2 million forfeiture
Regulators have responded. In February 2024, the FCC unanimously ruled that AI-generated voices count as "artificial" under the TCPA — meaning AI voice robocalls are illegal without prior express consent.
For any business that makes phone calls, this creates a clear dividing line. The same technology that powers scams can also power legitimate reminder, qualification, and follow-up campaigns — but only when consent, disclosure, and list discipline are built in from the start. That is why My AI Call Center runs campaigns only against approved, permissioned, or reviewed lists, with AI disclosure on every call and opt-outs honored immediately. Voice AI is powerful either way; the difference is whether the consent records exist before the phone rings.
If your organization uses outbound calls to confirm, qualify, remind, or retain, the question is no longer whether AI can copy a voice — it is whether your calling practices can stand up to the scrutiny that capability now invites.
Ready to run structured, consent-backed calling campaigns? Plan your campaign with My AI Call Center — managed outbound calling from 9¢ per connected minute, with list and consent review before anything launches.
What the Law Says: TCPA, the FCC Ruling, and Your Right of Publicity
The law has caught up to the technology. In February 2024, the FCC unanimously adopted a Declaratory Ruling classifying AI-generated voices as "artificial" under the Telephone Consumer Protection Act, making AI voice robocalls illegal without prior express consent. That ruling is not theoretical — it carried a proposed $2 million forfeiture against Lingo Telecom for 3,978 spoofed robocalls using a deepfake of President Biden's voice before the New Hampshire primary. The FCC's July 2024 Notice of Proposed Rulemaking goes further, proposing mandatory disclosure at the start of every call that an AI voice is being used.
Copyright does not protect a person's voice. The U.S. Copyright Office requires a human author, so raw AI audio files fall into the public domain. The real legal shield is the Right of Publicity — a person's right to control the commercial use of their identity, including their distinctive voice. That principle was established decades ago in Bette Midler v. Ford and Tom Waits v. Frito-Lay, where courts ruled that imitating a recognizable voice for commercial gain requires permission. As Respeecher's CEO puts it: the only question that matters is whether you have the artist's consent.
For any outbound campaign, that means three non-negotiables:
- Prior express consent for every contact on the list
- Clear AI disclosure on every call
- Real-time opt-out handling (STOP and REVOKE) synced across all campaigns
My AI Call Center builds these requirements into the launch process. Before a single call is placed, we review list source and consent records, approve the disclosure script, and verify the voice source — licensed voice actor, employee with documented consent, or ethically sourced vendor voice. If the consent trail is missing, the campaign does not launch. That discipline is not optional; it is the only way to run structured, useful calls without exposing clients to enforcement risk.
The Dark Side: How Cloned Voices Fuel Fraud at Scale
The phone rings. The voice on the other end sounds exactly like your daughter — panicked, breathless, begging for help. Only it isn't her. It's a synthetic replica built from a few minutes of audio scraped from social media, and the person controlling it is part of a transnational criminal network that treats voice cloning as a standard business tool.
According to the United Nations Office on Drugs and Crime, criminal operations in Southeast Asia weaponize artificial intelligence for deepfakes and voice cloning as part of an ecosystem that includes money laundering, malware, and cybercrime-as-a-service. The scale is staggering: the United States alone reported $10 billion in losses in 2024 from these scam operations. Victims are not only the elderly or unsophisticated. An Australian couple with master's degrees lost more than $2.5 million to an "extraordinarily believable" scammer who used a British accent and correct financial terminology to build trust over months.
The attack vectors are deliberate and varied. Emergency family scams exploit parental instinct. Executive vishing — voice phishing — impersonates a CEO or finance director to authorize fraudulent wire transfers. Political deepfakes manipulate public discourse. The University of Tennessee's security team notes that scammers create a sense of urgency to pressure you into acting quickly, because real emergencies rarely require instant decisions without verification.
Defending against this requires discipline, not just skepticism:
- Verify through a separate channel — call the person back on a known number, or contact another family member
- Resist urgency pressure; no legitimate emergency demands immediate payment without verification
- Limit public audio exposure — the less voice data available online, the harder cloning becomes
- Report suspicious calls to your security team or the FTC
At My AI Call Center, every campaign runs on approved, permissioned, or reviewed contact lists with AI disclosure on every call — because the same technology that enables fraud also demands a higher standard for legitimate use. When consent is documented, disclosure is mandatory, and opt-outs are honored in real time, outbound calling remains a trustworthy channel. The alternative is a race to the bottom that regulators are already moving to stop.
Running AI Calling Legally: Consent, Disclosure, and List Discipline
The FCC's February 2024 ruling didn't just clarify the rules for AI calling — it made the compliance bar explicit. AI-generated voices now count as "artificial" voices under the TCPA, which means prior express consent is required before an AI voice ever picks up the phone. Regulators are backing that interpretation with enforcement: the FCC proposed a $2 million forfeiture against Lingo Telecom for carrying 3,978 spoofed robocalls that used a cloned voice.
For organizations running legitimate AI calling, the operating model that follows is straightforward: consent first, disclosure always, opt-outs honored instantly. The FCC's July 2024 proposed rulemaking points toward mandatory disclosure at the start of every call that an AI voice is being used — a standard that responsible operators should treat as already in force.
A compliant campaign checklist looks like this:
- Prior express consent verified on every list, with source and consent records checked before launch — not after
- AI disclosure delivered at the start of every call, with recipients able to ask if the call is AI-assisted, request a human, or opt out
- Real-time opt-out handling through keywords like STOP and REVOKE, with DNC requests synchronized across campaigns and carried into client records
- Voice source verification — documented permission for any identifiable person's voice, consistent with Right of Publicity precedent from Midler v. Ford and Waits v. Frito-Lay
That last point matters more than most operators realize. As voice industry analysis makes clear, copyright offers no protection for raw AI voice files — the U.S. Copyright Office requires a "human author." The only real safeguard is the Right of Publicity: if an AI voice sounds like a specific person, you need that person's permission, full stop.
My AI Call Center builds this model into the campaign process itself. Every list is reviewed against an "approved, permissioned, or reviewed" standard before anything launches, and bought lists without clear permission records are flagged — in most cases, declined outright. Disclosure language, opt-out handling, and escalation paths are client-approved before the first call goes out, and opt-out and DNC logs ship with every campaign report.
The FTC has been blunt that self-regulation alone won't protect the public, and state Attorneys General can prosecute voice-cloning scams under state robocall laws that borrow TCPA definitions. The operators who treat consent, disclosure, and list discipline as campaign requirements — not legal afterthoughts — are the ones who will still be calling when the rules finish tightening.
Want to see whether your list can support a compliant campaign? Plan your campaign — managed outbound calling on approved, permissioned lists, from 9¢ per connected minute.
Questions to Ask Before You Approve Any AI Calling Campaign
The FCC's proposed $2 million forfeiture against Lingo Telecom — for carrying 3,978 robocalls using a cloned voice of President Biden — shows how expensive a careless AI calling campaign can be. Before you approve any campaign, the questions you ask up front matter more than the script itself.
Start with the list. Where did it come from, and is consent documented? Since February 2024, the FCC has treated AI-generated voices as "artificial" under the TCPA, which makes AI voice calls illegal without prior express consent. A bought list with no permission records cannot support a compliant campaign, no matter how good the offer sounds.
Next, ask about the voice itself. Ethical voice vendors draw a hard line here: industry guidance holds that the only question that matters is whether the person behind the voice gave permission — not who owns the audio file. A reputable provider uses licensed, consenting voice talent and discloses on every call that the voice is AI-assisted. If a vendor cannot answer where the voice came from, that is your answer.
Then press on opt-outs. A compliant program logs opt-outs in real time, honors them immediately, and carries do-not-call requests across every future campaign. Under the TCPA framework, legal analysis of recent FCC rulemaking shows disclosure and opt-out requirements are tightening, so yesterday's minimum is not tomorrow's standard.
Finally, ask to see the outcome report. It should show named disposition codes — confirmed, qualified, opted out, no answer — per-call notes, and completion coverage. If a vendor promises results without showing you how outcomes are counted, treat that as a red flag. The scale of AI voice fraud makes scrutiny non-negotiable: UN reporting documents $10 billion in U.S. losses in 2024 from scam operations that weaponize voice cloning.
A practical checklist before you sign anything:
- Where did the list originate, and are consent records on file?
- Is the AI voice ethically sourced from consenting talent, and is it disclosed on every call?
- How are opt-outs and DNC requests logged, honored, and synced across campaigns?
- What does the outcome report actually show — disposition counts, notes, and routed follow-ups?
This is the standard My AI Call Center applies to its own campaigns: lists are approved, permissioned, or reviewed before launch, and campaigns with unclear consent records are declined — plainly, before you spend anything. The first campaign review is free, so you can get real answers about your list, your script, and your compliance exposure before committing a dollar.
Frequently Asked Questions
How much audio does AI actually need to clone someone's voice?
Is it illegal to use an AI voice for robocalls?
Can I copyright my voice so nobody can clone it?
How big a problem is AI voice cloning fraud, really?
How can I tell if a phone call is using a cloned voice?
Can a business legally use AI voices for outbound calls?
The Voice Is Real. The Question Is Whether Your Consent Records Are.
AI can copy a voice from a few minutes of audio, criminals have turned that capability into a $10 billion fraud problem, and regulators are responding fast — the FCC now treats AI-generated voices as "artificial" under the TCPA, requiring prior express consent before a single call is placed. For any organization that uses the phone to confirm, qualify, remind, or retain, the dividing line is clear: the technology is neutral, but the consent trail decides whether your campaign is an asset or a liability. That means documented list consent, AI disclosure on every call, verified voice sources, and opt-outs honored in real time — all checked before launch, not after. If you cannot answer where your list came from or where the voice originated, you have your answer. Before you approve any AI calling campaign, ask those questions up front — and if you want them answered for you, My AI Call Center reviews list source, consent records, and compliance exposure in a free first campaign review, so you know exactly where you stand before spending a dollar.